monday.com logo
Apply to this job

Application Security Group Lead

InTechFullTimetelavivTel-Aviv, IL

About monday.com

monday.com is the AI work platform powering the most ambitious teams. 250,000+ customers across departments use us to bring people, workflows, and AI agents together on one flexible platform where AI doesn't just assist, it executes. We move fast, build things that matter, and foster an ownership-driven culture where you're empowered to shape how organizations work and outpace their competition.

About the Role

As our Application Security Group Lead, you will lead a group of talented security engineers, collaborating closely with Product, R&D and Internal Technology to embed security across every phase of the software development lifecycle (SDLC), CI/CD Security and Application Runtime Security in the era of agentic developer tools and environment. You will own the planning and execution of our global AppSec program, work with executives on strategic initiatives and drive a "secure-by-design" culture to ensure our agile deployment cycles never compromise on security.

Key Responsibilities

Strategic Leadership & Collaboration

  • Meet and engage with technical leaders within monday for fostering a culture of security ownership across R&D and providing visibility to risks across different teams

  • Define and execute a scalable application security roadmap aligned with monday.com’s rapid growth.

  • Work with the leadership team of the Security department on collaboration, shared projects and support for the culture within the department

Technical & Operational Oversight

  • Familiarity with utilization of AI in the development pipeline and overall application security risks in the AI stack

  • Seamlessly integrate automated security testing (SAST, SCA, Secrets) into CI/CD pipelines.

  • Lead the methodology for threat modeling sessions and architectural reviews for major platform changes, new features, and infrastructure updates.

  • Oversee our bug bounty program, penetration testing, and internal vulnerability disclosures, ensuring timely, risk-based remediation.

  • Partner with Governance, Risk, and Compliance (GRC) to ensure application compliance with application security related security controls as part of known frameworks (OWASP Top 10, ISO27001, SOC2, etc.)

People & Culture

  • Mentor, scale, and inspire a high-performing team of AppSec engineers; encourage continuous learning and innovation.

  • Act as a trusted advisor to product managers and engineering leads, balancing risk mitigation with business agility.

  • Contribute to the branding and positioning of the Security department.

Requirements

  • 8+ years in application security, with at least 4 years managing AppSec teams in cloud/SaaS environments.

  • Ability to see the bigger picture of monday’s product and system portfolio, prioritizing risks and activities.

  • Strong communication skills, able to translate complex security concepts into actionable recommendations for developers and executives.

  • Familiarity (preferably: hands-on experience) on mitigation against AI attack on product and application platforms (e.g. OWASP Top 10 for LLM)

  • Strong background securing cloud-native applications (AWS preferable) and expertise with general web application vulnerabilities (e.g., OWASP Top 10, CWE).

  • Proficiency in modern programming languages represented in our stack (e.g., Node.js, Ruby on Rails, React) and experience with Kubernetes, Docker.

  • Track record of implementing and optimizing AppSec tools in DevOps pipelines (GitHub, CI/CD tools).

If you are passionate about creating secure, scalable technology and leading with vision and technical depth, we'd love to meet you!

 
 

About monday.com

monday.com is the AI work platform powering the most ambitious teams. 250,000+ customers across departments use us to bring people, workflows, and AI agents together on one flexible platform where AI doesn't just assist, it executes. We move fast, build things that matter, and foster an ownership-driven culture where you're empowered to shape how organizations work and outpace their competition.

About the Role

As our Application Security Group Lead, you will lead a group of talented security engineers, collaborating closely with Product, R&D and Internal Technology to embed security across every phase of the software development lifecycle (SDLC), CI/CD Security and Application Runtime Security in the era of agentic developer tools and environment. You will own the planning and execution of our global AppSec program, work with executives on strategic initiatives and drive a "secure-by-design" culture to ensure our agile deployment cycles never compromise on security.

Key Responsibilities

Strategic Leadership & Collaboration

  • Meet and engage with technical leaders within monday for fostering a culture of security ownership across R&D and providing visibility to risks across different teams

  • Define and execute a scalable application security roadmap aligned with monday.com’s rapid growth.

  • Work with the leadership team of the Security department on collaboration, shared projects and support for the culture within the department

Technical & Operational Oversight

  • Familiarity with utilization of AI in the development pipeline and overall application security risks in the AI stack

  • Seamlessly integrate automated security testing (SAST, SCA, Secrets) into CI/CD pipelines.

  • Lead the methodology for threat modeling sessions and architectural reviews for major platform changes, new features, and infrastructure updates.

  • Oversee our bug bounty program, penetration testing, and internal vulnerability disclosures, ensuring timely, risk-based remediation.

  • Partner with Governance, Risk, and Compliance (GRC) to ensure application compliance with application security related security controls as part of known frameworks (OWASP Top 10, ISO27001, SOC2, etc.)

People & Culture

  • Mentor, scale, and inspire a high-performing team of AppSec engineers; encourage continuous learning and innovation.

  • Act as a trusted advisor to product managers and engineering leads, balancing risk mitigation with business agility.

  • Contribute to the branding and positioning of the Security department.

Requirements

  • 8+ years in application security, with at least 4 years managing AppSec teams in cloud/SaaS environments.

  • Ability to see the bigger picture of monday’s product and system portfolio, prioritizing risks and activities.

  • Strong communication skills, able to translate complex security concepts into actionable recommendations for developers and executives.

  • Familiarity (preferably: hands-on experience) on mitigation against AI attack on product and application platforms (e.g. OWASP Top 10 for LLM)

  • Strong background securing cloud-native applications (AWS preferable) and expertise with general web application vulnerabilities (e.g., OWASP Top 10, CWE).

  • Proficiency in modern programming languages represented in our stack (e.g., Node.js, Ruby on Rails, React) and experience with Kubernetes, Docker.

  • Track record of implementing and optimizing AppSec tools in DevOps pipelines (GitHub, CI/CD tools).

If you are passionate about creating secure, scalable technology and leading with vision and technical depth, we'd love to meet you!

 
 
Apply to this job

Autofill from Resume

Upload your resume to automatically fill in your application details


Basic Info


Please review our privacy practices: Privacy policy: monday.com

Apply to this job

Autofill from Resume

Upload your resume to automatically fill in your application details


Basic Info


Please review our privacy practices: Privacy policy: monday.com

We believe in equal opportunity.

At monday.com, we believe everyone should feel they belong - exactly as they are. We’re an equal opportunity employer, committed to an open, accessible, and inclusive workplace free from discrimination or harassment of any kind.

All qualified candidates will be considered for employment, regardless of race, color, religion, nationality, sexual orientation, gender identity, age, marital status, pregnancy, family or parental status, disability, veteran status, or any other characteristic protected by law.

If you need support or accommodation during the hiring process, we’re here to help.

Meet the InTech team

The Information Systems and Data Organization aims to empower Monday's employees to perform at their best in their core professions.

Our team focuses on three main things - Support business processes effectively, support our information systems, ensure our technology infrastructure is optimized, and provide insights into our data in order to make informed decisions.